Crypto's First Quantum Attack May Look Like an Ordinary Key Theft, Quantus Founder Warns
Key Takeaways
- •A quantum-enabled attack on cryptocurrency wallets would leave no conventional forensic evidence, as attackers could derive private keys directly from exposed public keys without breaching devices or systems.
- •Experts believe the first crypto-related quantum targets may be Tether's minting key or exchange hot wallets rather than Satoshi Nakamoto's dormant Bitcoin, which is valued at approximately $63 billion.
- •Google accelerated its post-quantum migration timeline to 2029 after an AI-assisted breakthrough showed elliptic curve cryptography can be cracked with fewer physical qubits than previously estimated.
- •There is no consensus on when Q-day will arrive, with estimates ranging from a 50 percent chance by 2028 to near certainty by the early 2030s.
- •The US National Institute of Standards and Technology released its first finalized post-quantum cryptography standards in August 2024, and several blockchain networks have already begun migrating to quantum-resistant signatures.

[Update 03:40 UTC, Aug. 11: Includes comments from Binance chief security officer Jimmy Su.]
The earliest indication that quantum computing has broken modern cryptography will likely not be a dramatic theft of Satoshi Nakamoto's dormant Bitcoin. Instead, it could manifest as a series of seemingly unrelated crypto wallet breaches with no discernible attack vector, according to Christopher Smith, CEO and co-founder of Quantus Network.
"When someone cracks your key, you don't get a memo saying how they did it," Smith told Cointelegraph. A sufficiently powerful quantum computer could derive a private key from public keys exposed onchain, enabling an attacker to move funds without compromising a wallet, device, or exchange's internal systems.
This characteristic makes the arrival of "Q-day" — the hypothetical future point at which quantum computers become powerful enough to break standard public-key cryptography — exceptionally difficult to detect. In a theft targeting a highly secure organization, "the only forensic evidence would be that there was no breach," Smith said.
Smith's warning follows advances in quantum algorithms that have reduced the estimated computing resources required to attack the elliptic-curve cryptography employed by major blockchains. The same family of algorithms — specifically ECDSA and related schemes — also underpins much of the internet's secure communications, meaning a sufficiently capable quantum machine would have implications well beyond the crypto industry.
First Target May Not Be Satoshi's Bitcoin
Much of the concern surrounding Q-day in the crypto space centers on the prospect of a quantum computer cracking the keys that secure Satoshi Nakamoto's estimated Bitcoin holdings, valued at approximately $63 billion at the time of writing, which could be abruptly liquidated on the market.
However, Smith suggested that the first targets may be military systems and state secrets, while crypto-focused attackers might pursue even higher-value keys.
"If I'm focusing on blockchain, what's the single most valuable key? It's probably Tether's minting key," Smith said. A quantum attacker could mint tokens from an administrative wallet and offload them on the market before the issuer could respond, he added.
USDT is a multi-chain stablecoin, and some of the networks on which it is deployed are already actively working on post-quantum migration.
Another theory suggests that attackers would opt for a quieter opening move. Sean Cheetham, a security researcher at Blockchain Capital, said an attacker would more likely target hot wallets at exchanges "that aren't going to ring alarm bells rather than stealing Satoshi's coins."
Smith added that an attacker may deliberately disguise a quantum-enabled theft as a conventional compromise.
"There's an alternative scenario where they… have these plausible, deniable [explanations]: 'Oh, somebody just lost their keys somehow,'" he said.
Q-Day Timeline Remains Uncertain
In March, Google accelerated its post-quantum migration timeline to 2029 after an AI-assisted breakthrough demonstrated that elliptic curve cryptography can be cracked with far fewer physical qubits than previously estimated.
Binance chief security officer Jimmy Su said AI could hasten the approach of Q-day by helping researchers overcome engineering hurdles that still constrain quantum computers.
"AI doesn't suddenly turn today's quantum computers into machines capable of breaking modern cryptography," Su told Cointelegraph. "But it can accelerate the research and engineering process that gets us there." He noted that machine learning could help optimize quantum systems, improve error correction and control, and accelerate the development of new algorithms and hardware.
NGRAVE CEO Roy Blackstone observed that earlier quantum forecasts failed to account for the parallel advancement of AI. "Most threat models assumed we had well into the next decade before quantum technology could realistically crack the cryptography securing public keys, but it did not account for how fast AI would develop alongside it."
The broader cybersecurity community has already begun formalizing post-quantum defenses. In August 2024, the US National Institute of Standards and Technology released its first finalized post-quantum cryptography standards, providing a reference for organizations transitioning away from vulnerable algorithms.
Despite growing urgency, there is little consensus on when a quantum computer capable of breaking modern cryptography will become operational.
Smith, whose company is developing a blockchain network designed to be quantum-resistant from launch, placed the probability of Q-day arriving by 2028 at "50-50," arguing that continued AI-assisted improvements in quantum algorithms and hardware research are making forecasts less reliable.
Cheetham said the early 2030s "definitely is almost a certainty" and that an earlier arrival was "more of a trailing probability."
Michael Coates, the Solana Foundation's chief information security officer, declined to provide an estimate during an earlier interview, stating, "there's no way to know." He added: "If you talk to people in the industry, it is always five years away, and it's been that way for 10 years or more now. Perhaps today people say it's four years away." However, he stressed that uncertainty is not a reason to delay preparation.
"Thankfully, blockchains aren't waiting and have started migrating to post-quantum signatures," said Blackstone. "The damage would be catastrophic if they didn't."